Breaking
Cyber CrimeDeveloping Story

Allies Map North Korea IT Worker Web

A four-nation advisory ties a fake-recruiter hacking crew to North Korea's IT worker scheme and details Japan's first laptop farm takedown.

··1 hour ago·7 min read
person using macbook pro on brown wooden table
Photo by Justin Morgan on Unsplash

Four countries have now put their names on the same conclusion: the hackers who pose as recruiters to burrow into developer workstations and the IT contractors who quietly collect paychecks from Western employers are, in important respects, the same operation. Law enforcement and intelligence agencies from Japan, the United States, Australia and Germany released a joint advisory that attributes a long-running hiring scheme to a North Korean group they call WaterPlum, also known as Contagious Interview.

The document sketches the group's tradecraft, links some of its members to North Korea's broader IT-worker scheme, and describes Japan's first-ever takedown of a North Korean laptop farm. It arrives as a single outlet's account of a multi-agency product, so the specifics below should be read as the agencies' findings as reported by SecurityWeek.

WaterPlum Poses as Hiring Managers

According to the advisory, WaterPlum reaches software developers and IT professionals by pretending to be employers, frequently impersonating real AI, cryptocurrency or NFT companies. The group has also leaned on legitimate recruiting services to make first contact — a detail that matters because it means a candidate cannot always filter the approach by checking whether the recruiter's domain is fake.

The targeting is narrow and deliberate. The advisory says its primary targets were web designers, engineers and specialists in cryptocurrency, blockchain and web3. Those are roles with access to codebases, cloud credentials and, in the crypto case, keys to funds.

The timeline in the document is measured in months, not years. Between December 2025 and July 2026, WaterPlum infected at least 30,000 devices across more than 100 countries. Funds or account credentials were taken from more than 7,000 cryptocurrency wallets, and the agencies estimate that roughly $10.71 million ultimately reached North Korea.

Those numbers describe a campaign that operated at scale while remaining, from the victim's side, a series of one-to-one conversations with a person who seemed to be hiring.

A Shared Address Book

The most consequential claim in the advisory is about command and control of a different kind: who the operators answer to. The National Police Agency of Japan and the FBI assess that WaterPlum operators and some North Korean IT workers answer to the same part of the regime — the 313 General Bureau of the Munitions Industry Department, under the Workers' Party of Korea's Central Committee.

The agencies also state that WaterPlum actors and North Korean IT workers have been seen using the same IP addresses, including when accessing laptop farms and applying for jobs. That overlap is the connective tissue the advisory uses to argue the two activities are not parallel but shared.

For defenders, the practical effect is that an intrusion traced to a fake job interview and an employee who turns out to be an overseas contractor may not be separate incidents. They may be two ends of one pipeline.

The Damage Beyond Wallets

The agencies were explicit that the loss does not stop at drained crypto accounts. A compromised developer can give WaterPlum a path into their employer's network, according to the advisory, and the group has also used stolen data for extortion or to access personal information and trade secrets.

That description reframes the victim profile. A developer's laptop is not just a place where a wallet lives; it is a position inside a corporate environment with source code, internal systems and, often, privileged access to cloud infrastructure. The advisory's account of extortion fits a group that treats stolen data as leverage after the initial access has served its purpose.

Japan's First Laptop Farm Takedown

Part of the scheme depends on physical infrastructure the workers never touch themselves. So-called laptop farms are locations — often an accomplice's residence — where devices are set up and then run remotely by North Korean IT workers. The accomplices also manage servers on the workers' behalf, masking the workers' real location while they carry out paid IT work.

According to the advisory, Japan dismantled one such laptop farm this year, the first case of its kind the country has confirmed.

"Japanese authorities obtained evidence this cyber actor group transferred several hundred million Japanese yen in cryptocurrency to foreign locations outside of Japan," the document states.

The advisory attributes that statement to the joint document itself rather than to a named individual. Separately, the FBI says it continues to identify and prosecute US-based individuals who provide facilitation services to North Korean IT workers.

The Japanese case illustrates the physical footprint these operations require: a room full of machines, someone local to host and maintain them, and financial plumbing to move proceeds out of the country.

Telltale Signs From a Rejected Applicant

The advisory describes a case from a Japanese cryptocurrency exchange that turned down a suspicious applicant in May 2025. The candidate applied through a VPN with a resume claiming more than ten areas of expertise each across programming languages, blockchain technologies and cloud services. He also claimed a European university degree and vast job experience across Europe and Asia.

On a video interview, the applicant said he was born in Malaysia, lived in Finland, and spoke Malay and Chinese as native languages. His English, the advisory notes, "did not match his claimed academic and professional background," and he could not explain most of the skills listed on his resume.

Interviewers who encountered other suspected North Korean IT workers reported similar patterns, including reluctance to meet in person, requests to be paid in cryptocurrency, and applicants who appeared to glance at a second screen as if reading answers. Some calls featured unexplained background voices or repeated audio and video freezes.

The agencies noted that WaterPlum operators frequently used AI face-swapping during initial video calls, cutting their feeds minutes into the interview under the guise of technical difficulties to evade detection.

Other behaviors the advisory catalogues are less technical and more human: operatives practicing Japanese pronunciation with text-to-speech tools, relying on free machine-translation services, or stepping away from their usual work on North Korean holidays to watch soccer or play games.

The Numbers Behind the Advisory

  • At least 30,000 devices infected across more than 100 countries between December 2025 and July 2026
  • Funds or credentials taken from more than 7,000 cryptocurrency wallets
  • Roughly $10.71 million estimated to have reached North Korea
  • Several hundred million Japanese yen in cryptocurrency transferred abroad, per evidence obtained by Japanese authorities
  • A rejected applicant in May 2025 who claimed more than ten areas of expertise each in programming languages, blockchain technologies and cloud services

The wallet and device figures are the agencies' assessments, not independently verified counts. The yen figure is described as evidence Japanese authorities obtained in the laptop farm case.

Why the Hiring Pipeline Matters

The advisory's portrait of recruitment is the part most employers can act on. A résumé that claims implausible breadth, a candidate who avoids in-person meetings, payment demands in cryptocurrency, and video calls that freeze or drop at convenient moments are all flags the document lists. AI face-swapping during initial calls adds a layer that a decade-old hiring checklist would not catch.

The overlap with the IT-worker scheme complicates the picture further. The advisory states that WaterPlum actors and North Korean IT workers have used the same IP addresses when applying for jobs and accessing laptop farms, and that both answer to the 313 General Bureau. For a company, that means the fake recruiter who targets an employee and the contractor who applies for a remote role may be drawing on the same infrastructure and the same handlers.

The FBI's stated position is that it continues to identify and prosecute US-based individuals who facilitate North Korean IT workers — a reminder that the scheme requires people on the ground in the countries being targeted, not just operators overseas.

What This Means for Defenders

The advisory does not offer a compliance checklist, but its contents point to where the risk concentrates. Hiring teams that cannot verify a candidate's identity beyond a video call are exposed to the same impersonation techniques the Japanese exchange caught in May 2025. Companies that treat remote contractors as low-risk because they hold no full-time badge may be underestimating what a developer's credentials reach.

The financial trail matters too. The Japanese case shows cryptocurrency moving out of the country in the hundreds of millions of yen, and the advisory's estimate of roughly $10.71 million reaching North Korea ties the activity to revenue, not just espionage. That dual purpose — access and income — suggests organizations may need to treat suspicious hiring activity and suspicious network activity as related signals rather than separate ones. The same part of the regime, according to the agencies, sits behind both.

#north korea#laptop farms#waterplum#it worker scheme#recruitment fraud#cryptocurrency theft

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories